CVE-2026-86351
- EPSS 0.33%
- Veröffentlicht 07.09.2026 09:59:34
- Zuletzt bearbeitet 09.09.2026 15:26:26
Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacker.example also begin with / but resolve to an exter...
CVE-2026-86347
- EPSS 0.29%
- Veröffentlicht 07.09.2026 09:30:58
- Zuletzt bearbeitet 09.09.2026 15:26:35
Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring template-manage...
CVE-2026-86342
- EPSS 0.27%
- Veröffentlicht 07.09.2026 09:02:55
- Zuletzt bearbeitet 09.09.2026 15:22:56
Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event...
CVE-2026-86283
- EPSS 0.23%
- Veröffentlicht 06.09.2026 14:15:06
- Zuletzt bearbeitet 08.09.2026 19:20:12
MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolve...
CVE-2026-85547
- EPSS 0.34%
- Veröffentlicht 04.09.2026 09:40:54
- Zuletzt bearbeitet 08.09.2026 14:11:18
A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identified as a REST request. MISP's REST detection can be influenced by request prope...
CVE-2026-85546
- EPSS 0.2%
- Veröffentlicht 04.09.2026 09:27:36
- Zuletzt bearbeitet 10.09.2026 08:17:01
MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, where the HTTP method validation int...
CVE-2026-85538
- EPSS 0.3%
- Veröffentlicht 04.09.2026 09:05:41
- Zuletzt bearbeitet 08.09.2026 14:11:18
An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions. The affected attribute deletion paths relied on organization membe...
CVE-2026-85533
- EPSS 0.22%
- Veröffentlicht 04.09.2026 08:53:46
- Zuletzt bearbeitet 08.09.2026 14:11:18
An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing Group. In several attribute and Galaxy Cluster creation and editing workflows, vali...
CVE-2026-85239
- EPSS 0.24%
- Veröffentlicht 03.09.2026 15:37:47
- Zuletzt bearbeitet 11.09.2026 14:18:55
A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed sema...
CVE-2026-85238
- EPSS 0.23%
- Veröffentlicht 03.09.2026 15:30:42
- Zuletzt bearbeitet 11.09.2026 14:17:04
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without ...